Applications arrive as PDFs and identity documents arrive as phone photographs attached to e-mail. Someone eyeballs a passport against a form. When the regulator asks how a decision was reached, the evidence is scattered across a mailbox and the identity check was a person's judgement with nothing behind it.
Take finance applications online, with KYC built in.
The compliance risk is obvious once stated: identity document images sitting in a mailbox are among the most sensitive data you could hold, they are held in the least controlled place you have, and holding them is not actually necessary for the check you needed.
The quieter problem is that a human comparison of a document to a form produces a decision with no evidence behind it. It might have been a good decision. There is nothing on file establishing that it was, which is precisely what a regulator or an insurer will ask for — not whether you checked, but what the check consisted of and what it returned.
And commercially, a long form with an e-mail step in the middle loses applicants. Every handoff is an opportunity to stop, and because the abandonment is invisible, nobody knows whether the loss is at question three or question thirty.
A staged application form with save-and-resume, so a long application can be finished later rather than abandoned, and conditional fields so applicants only see what applies to them. Because it is staged, you can see where people stop.
Identity verification is wired into the flow rather than bolted onto the end. The applicant photographs their passport, driving licence or national identity card and normally takes a selfie, which is matched against the document. The check runs through Onfido or Stripe Identity in the provider's own flow, so document images never pass through your application and you are not storing them. The result comes back against the applicant's record.
From there, underwriting rules route the application, an authorisation step records who signed it off, and each check type carries a validity period so a fact that stops being true expires and is asked again. A result from an unknown or disabled provider, or one without a valid signature, is refused rather than trusted — the check fails closed, which is the only safe default.
A multi-stage form with conditional sections and save-and-resume. Applicants see only what applies to them, can stop and come back, and because each stage is a recorded step you find out where abandonment actually happens.
Document and biometric checks run through the provider's own flow at the point in the application where they belong. The applicant photographs a passport, licence or ID card and takes a selfie; the images go to the provider, not to you.
A pass can proceed automatically or be held for a manual review queue with the evidence shown alongside the decision. Sign-in itself can be gated on a required check. An unsigned or unrecognised result is refused rather than treated as a pass.
Underwriting rules send applications down the right path by value, product or risk, and an electronic authorisation step records the sign-off — who, when, and against what the record contained at that moment.
Each check type has a validity period, so verification is a fact with a lifespan rather than a permanent tick. Scheduled tasks ask again before it lapses instead of after someone notices.
Nothing here is written specially for this use case — it is the same platform every ActiveManage application is built from. The full feature list is on the platform page.
| Feature | What it does | Why it matters here |
|---|---|---|
| ID document checks | The applicant photographs a passport, driving licence or national identity card and normally takes a selfie, matched against the document. | Replaces a member of staff forming a view about a photograph with a check that produces a recorded result. |
| Onfido & Stripe Identity | Checks run in the provider's own flow, so document images never pass through your application. | You get the assurance without becoming the custodian of a pile of passport photographs. |
| Validity & re-verification | Each check type carries a validity period, after which the user is asked again. | Verification is a fact that expires. Treating it as permanent is how files quietly become non-compliant. |
| Manual review queue | A provider pass can be held for an administrator to confirm, with the evidence shown alongside. | Keeps a human in the loop where your risk appetite requires one, without making the human the whole control. |
| Fails closed | A result from an unknown or disabled provider, or without a valid signature, is refused rather than trusted. | The correct default, and not a universal one. A verification system that fails open is worse than none, because it is believed. |
| Multi-stage forms & auditing | Staged forms with save-and-resume and conditional fields, over a full change history. | Fewer abandoned applications, and a complete record of how each decision was reached. |
The application form and the verification step, end to end, against a provider sandbox. Getting the identity flow right early matters because it shapes everything around it.
Underwriting routing, the review queue, authorisation, expiry handling and whatever the application has to hand off to afterwards.
Questions, routing rules and validity periods are configuration — which matters, because regulatory requirements change more often than software budgets.
No, and that is much of the point. The check runs in Onfido's or Stripe Identity's own flow, so document images never pass through your application. You hold the result and the evidence of the check, not the document.
Passports, driving licences and national identity cards, normally with a selfie matched against the document.
It goes to a manual review queue where an administrator sees the evidence alongside the decision. You choose which outcomes route there rather than accepting a provider's default.
Each check type carries a validity period, so the platform knows when a verification has lapsed and can ask again — and can gate access on a required check where that is appropriate.
It can route them automatically on your rules, and record the authorisation when a person signs off. Whether any decision is fully automated is your call and your regulatory responsibility — the platform will not make that choice for you.
Tell us what you are trying to fix and we will tell you whether this is the right shape for it — including when it is not.