SardineCon SF/2026

Learn More

O que é Onboarding?

SUBSCRIBE

Onboarding is the full process of bringing on a new customer, covering identity verification, due diligence, screening, and initial risk scoring before any activity is allowed. It is the primary chance to keep bad actors out, and the decisions made here set the baseline every later control leans on.

What is onboarding, in plain English?

Onboarding is everything that happens between a customer saying they want an account and the firm letting them use it. It bundles identity verification, due diligence, screening, and an initial risk score into one gate. Done well, it confirms the person is who they claim, checks them against sanctions and watchlists, gathers the information needed to understand their expected activity, and assigns a starting risk rating, all before money moves.

It is the first and best chance to keep bad actors out. Once an account is live, removing a bad customer is slower, costlier, and often only possible after damage is done. That is why onboarding carries so much weight: it is the one moment where the firm holds all the leverage and the customer has not yet acted.

The tension is that onboarding also sits directly against conversion pressure. The business wants signups fast and frictionless, while risk wants enough scrutiny to be safe. The resolution is a risk-based approach: light-touch flows for low-risk customers, more checks where signals warrant, and a clean handoff of everything learned into ongoing monitoring so the effort is not wasted after approval.

The stages of onboarding

A typical onboarding gate runs through a sequence of checks before access is granted:

  1. Collect — Capture the application. Gather identity details, contact data, and, for businesses, ownership and structure information.
  2. Verify — Confirm identity. Validate the identity through document, data, or biometric checks so the person is who they claim.
  3. Screen — Check against risk lists. Run sanctions, PEP, and adverse-media screening to catch prohibited or high-risk parties.
  4. Score — Set the risk baseline. Assign an initial risk rating that decides the level of diligence and the intensity of later monitoring.
    • Low risk — Streamlined path. Lighter verification and simplified diligence where low risk is genuinely evidenced.
    • High risk — Enhanced path. Deeper checks, source-of-funds questions, and closer ongoing scrutiny.

What it looks like in practice

In practice

A fintech launches a fast signup flow to boost conversion, and the product team trims the number of onboarding checks to reduce drop-off. Signups jump, but within weeks the fraud team sees a cluster of new accounts sharing a handful of devices and addresses, all funded and drained within days.

On review, the trimmed flow had stopped passing device and address signals into monitoring, so the pattern that was visible at signup never reached the team watching activity. The fix is not just tighter onboarding; it is making sure the risk data gathered at the gate feeds the controls that run afterward. Onboarding did see the signal; the process had simply thrown it away.

Why onboarding matters to operators

Onboarding sets the baseline every later control leans on. The initial risk rating decides how closely a customer is watched, what diligence they need, and which alerts fire on their activity. If the baseline is wrong, monitoring is mis-tuned from day one, either missing real risk or drowning analysts in noise.

It is also where a lot of institutional knowledge gets created and, too often, lost. The device, address, and behavioral signals captured at signup are some of the richest a firm ever sees for a customer. If they are discarded after approval, downstream monitoring is flying blind. Get onboarding right once, and everything after has something solid to build on.

What to watch for

  • Conversion pressure eroding controls. Checks quietly removed to reduce drop-off can open gaps that only show up as losses later.
  • Signals not carried forward. Device, address, and behavioral data captured at signup must feed monitoring, not vanish after approval.
  • Shared identifiers at scale. Many new accounts on the same devices, addresses, or funding sources is a classic new-account-fraud pattern.
  • Mismatched risk scores. A baseline that does not fit the customer's real profile mis-tunes every later control.
  • Synthetic and stolen identities. Onboarding is where synthetic and stolen identities try to get in, so verification depth should match risk.

Quick questions

How is onboarding different from KYC?

KYC is a core component of onboarding, focused on verifying and understanding the customer. Onboarding is the broader process that also includes screening, initial risk scoring, and the decision to grant access.

Why is the initial risk score so important?

Because it sets how intensely the customer is monitored and what diligence they receive. A wrong baseline mis-calibrates every downstream control, either letting risk through or flooding analysts with false positives.

How do firms balance friction and safety at signup?

With a risk-based approach: streamlined flows for demonstrably low-risk customers and deeper checks where signals warrant. The goal is proportionate scrutiny, not the same burden on everyone.

What happens to the data gathered at onboarding?

It should feed ongoing monitoring and the customer risk profile. If it is discarded after approval, later controls lose the context they need and effectively start blind.

Is onboarding a one-time event?

The initial gate is, but the relationship it opens is monitored continuously and refreshed through ongoing and periodic review. Onboarding sets the baseline; later controls keep it current.

What fraud types target onboarding directly?

New-account and application fraud, synthetic identity, and identity theft all aim at the onboarding gate, since that is where an account first gets created and funded.

Go deeper

  • FFIEC BSA/AML Examination Manual ↗ — The manual US examiners use to assess BSA and AML programs.
  • FATF ↗ — The global standard-setter for AML, counter-terrorist-financing, and counter-proliferation. Recommendations, guidance, and jurisdiction lists.

O que saber junto com Onboarding