KYC document checks, on the device
Blur detection, OCR, masking, watermarking, liveness and face match moved from paid vendor APIs to the customer's own phone, with face match on the company's own servers.
- Sector
- Housing finance, onboarding
- Period
- 2025 to 2026
- The number
- Per-call cost to zero
The leak
Every customer who onboards uploads identity documents and a selfie. Before anything is stored, a chain of checks runs: is the image usable, what does it say, which parts must be hidden before storage, is the person in the selfie real and present, is it the same person as on the document. When I arrived, each link in that chain was a separate vendor API. Each one charged per call, so the cost of onboarding grew in step with every new customer, which is the wrong direction for a cost to grow in. Together the chain was a recurring bill large enough to be a line item on its own.
The constraint
The phones at the bottom of the market set the floor. Anything that ran on the device had to run on the cheapest, slowest handset the customer base uses, which ruled out heavy models and meant every component had to be small.
Identity numbers carry rules about which digits may be stored, so masking had to be exact and verifiable, not a best effort. The stored photo also had to be consistent: a face on a plain background, captured at the right moment.
And the vendor was the benchmark. Nothing could be switched off until the replacement was at least as accurate on the same documents, measured, not assumed.
The system
Most of the chain now runs on the phone, in the onboarding app itself. A blur check rejects an unusable photo before it is uploaded, which also saves the round trip. Text recognition and a compact classifier tell one document type from another and read the fields that matter, with a small named-entity model trained for the handful of entity types the lender actually needs. Masking follows from recognition: once the digits and codes that must not be kept are located, covering them is exact. Watermarking marks the ones that are kept. Background removal takes the selfie to plain white so the photo on file is uniform.
Liveness was rebuilt rather than bought. Instead of a passive check that analyses one frame for signs of a screen or a print, the app issues random challenges, turn left, turn right, blink, with clear instructions, and captures the frame at the moment the person has just complied. It is harder to spoof, needs no model, and produces a better photo for the next step.
Face match is the one step that stayed server-side, because it genuinely needs a model that a low-end phone cannot run well. It runs on open face-recognition models, repurposed and tuned for the kinds of documents and selfies the lender actually sees, hosted on the company's own servers. The cost of a match is the server, which does not change when the hundredth customer becomes the thousandth.
The number
Per-call cost to zero for every check except face match, and face match costs servers rather than a vendor. The chain is being switched off one link at a time, as each on-device component proves itself against the vendor on live traffic, with the saving noted before each cutover.
What I would do differently
Measure accuracy against the vendor from the first week, on the same test set, so that each component carries its own proof on the day it is proposed. The comparison was added later than it should have been, and switching a vendor off is a decision that wants evidence in hand, not a leap.