SardineCon SF/2026

Learn More
Identity verification4 min de leitura

O que é eKYC?

SUBSCRIBE

eKYC is fully digital, remote KYC that swaps in-person checks for document capture, biometric liveness and face match, and data-source checks. It lets you onboard customers anywhere without a branch visit, but it concentrates the risk at the capture step, where injection attacks, deepfakes, and coached applicants all aim.

What is eKYC, in plain English?

eKYC is know your customer done entirely online, with no branch and no clerk. Instead of a person checking your passport at a counter, the customer captures their document, takes a selfie with a liveness check, and the system runs a face match and data-source checks in the background. The whole thing happens on a phone in minutes, which is what makes remote onboarding at scale possible.

Because it removes the physical touchpoint, eKYC concentrates the risk at the capture step. That single moment, when the document and face are collected, is where nearly every attack aims: injection attacks that feed fake media straight into the pipeline, deepfakes that fabricate a face, and coached applicants being walked through by a fraudster off-screen.

In fraud and AML, eKYC is the modern default for digital onboarding. The important design principle is layering: strong eKYC combines document, biometric, device, and data signals and cross-checks them against each other, because any single channel can be spoofed on its own.

How an eKYC flow runs

  1. Document — Capture the ID. The customer photographs their document, which is authenticated for genuineness and edits.
  2. Biometric — Selfie with liveness. A live selfie confirms a real, present human and is face-matched to the document photo.
  3. Data — Cross-check the sources. Extracted details are matched against authoritative records and the application data.
  4. Device — Check the channel. Device integrity and capture provenance guard against injection, emulators, and virtual cameras.

Who is involved?

Who

Their role

The customer

Completes the capture steps on their own device during remote onboarding.

The eKYC vendor

Runs document, biometric, device, and data checks and returns a combined decision.

The compliance team

Owns the KYC obligation and sets what evidence is required to onboard.

The fraudster

Attacks the capture step with injection, deepfakes, or a coached victim in front of the camera.

What it looks like in practice

In practice

A neobank onboards customers through an app: snap the ID, take a selfie, done in two minutes. One application clears the face match with a strong score, but the device signals show the selfie arrived through a virtual camera rather than the real front camera.

That mismatch is the tell. The face was a deepfake injected straight into the pipeline, so the biometric passed while the capture was fake. Because the flow cross-checked the device channel against the image, it caught what the face match alone rated as a clean pass. The account is held for review instead of onboarded.

Why it matters to operators

eKYC is what lets a business onboard customers across a country or the world without physical branches, which is now table stakes for digital finance. Done well, it clears good customers in minutes while meeting the same KYC obligations a counter clerk once handled.

The catch is that every eye is on the capture step. Because a single moment carries all the assurance, a weak eKYC flow that trusts one channel is easy to beat with a deepfake or an injected feed. Strong eKYC layers document, biometric, device, and data signals and reconciles them, so passing requires beating all of them at once rather than fooling one.

What to watch in the data

  • Virtual camera capture. A selfie that arrives through an emulator or virtual camera rather than the real sensor is a prime injection signal.
  • Perfect face, odd device. A strong face match paired with tampered device or provenance signals is a classic deepfake tell.
  • Coaching cues. Long pauses, off-screen prompting, or a distressed applicant can mean someone is being walked through the flow.
  • Single-channel pass. Onboarding cleared on one signal alone, with the others thin or skipped, is under-verified.
  • Data disagreement. Extracted document data that does not reconcile with the sources or application deserves a hold, not an override.

Quick questions

How is eKYC different from KYC?

KYC is the obligation to know your customer. eKYC is one way to meet it, fully digital and remote, using document capture, biometrics, and data checks instead of an in-person review.

Why is the capture step the weak point?

Because it is the one moment that carries all the assurance. Injection attacks, deepfakes, and coached applicants all target it, so if that step is trusted blindly, the whole flow can be beaten there.

What is an injection attack in eKYC?

It is when fake media is fed straight into the verification pipeline through a virtual camera, emulator, or intercepted API, bypassing the real camera. Liveness alone often misses it, so device and provenance checks matter.

Does a strong face match mean the person is real?

Not by itself. A deepfake can produce a high match score, so the face match only means something with liveness and capture-provenance checks confirming the image came from a genuine camera.

What makes an eKYC flow strong?

Layering. It combines document, biometric, device, and data signals and cross-checks them against each other, so a fraudster has to defeat every channel at once rather than spoofing a single one.

Go deeper

  • NIST Digital Identity Guidelines (SP 800-63) ↗ — The US standard for identity proofing and authentication assurance levels.
  • FATF ↗ — The global standard-setter for AML, counter-terrorist-financing, and counter-proliferation. Recommendations, guidance, and jurisdiction lists.

O que saber junto com eKYC