Common questions about WhoYou verification, KYC, biometrics, integration, privacy and pricing.
Know Your Customer (KYC) is the process a business uses to establish and verify who its customers are and assess the risks associated with doing business with them. For accountable institutions in South Africa, KYC forms part of broader customer due diligence obligations under the Financial Intelligence Centre Act (FICA).
Effective KYC helps businesses prevent identity fraud, money laundering and other financial crime while creating reliable customer records and an auditable compliance process. It should be proportionate to the risk involved: lower-risk interactions may require fewer checks, while higher-risk customers or transactions may require stronger verification and additional due diligence.
These terms are related, but they are not interchangeable. KYC is the process of identifying a customer, verifying their identity and understanding the risk they may present. FICA is the South African law that places customer due diligence, record-keeping, reporting and other obligations on accountable institutions. AML, or anti-money laundering, is the broader framework of controls used to prevent, detect and report money laundering and related financial crime. Identity verification is one component of KYC. It confirms that the identity information supplied is valid and, where biometrics are used, that the person presenting it is the genuine identity holder.
WhoYou provides identity, biometric, data and compliance services that organisations can use as building blocks within their wider KYC and AML programmes.
WhoYou provides digital identity infrastructure across the customer lifecycle. Depending on the solution selected, businesses can validate identity information against trusted sources, verify faces or fingerprints, perform liveness and anti-spoofing checks, capture and assess identity documents, screen against risk data, manage exceptions and retain an audit trail of the verification.
WhoYou also provides access to government, bureau and third-party data services through a unified platform. This enables businesses to support onboarding, ongoing authentication, fraud prevention, compliance checks, customer-data enrichment and other identity-sensitive processes without integrating separately with every underlying source.
WhoYou supports regulated and identity-sensitive organisations across sectors including banking, fintech, insurance, iGaming, telecommunications, retail, healthcare, government, automotive, education, travel, logistics and security services.
Common use cases include digital customer onboarding, KYC and FICA checks, biometric authentication, policyholder or claimant verification, secure payouts, account recovery, bank-detail changes, SIM or account activation, fraud screening, customer-data enrichment and ongoing identity management. The verification journey can be tailored to the risks, systems and customer experience requirements of each organisation.
Yes. WhoYou can verify a person during onboarding and authenticate them again when a later interaction carries additional risk. For example, a business may request biometric authentication when a customer resets a password, changes contact or bank details, submits a claim, requests a payout or performs another sensitive action.
This approach helps organisations move beyond once-off KYC. A previously verified identity can become the trusted foundation for future authentication, subject to the organisation's risk rules, consent requirements and configured verification process.
The exact journey depends on the customer's country, the information available and the checks selected by the organisation. A typical process: the customer opens a secure verification link or begins the process inside the organisation's digital journey, the purpose of the verification and privacy or consent information are presented, the customer supplies an ID number or passport information and may capture a selfie, fingerprint or identity document, WhoYou performs the configured checks (data-source validation, document extraction, biometric matching, liveness detection, fraud screening), and a result and supporting evidence are returned to the organisation through the portal, an API or an integrated workflow.
If a preferred source or biometric is unavailable, the journey can follow an approved alternative path, such as document capture or exception review.
Simple biometric or data-verification journeys can often be completed in seconds, provided the customer has a supported device, a stable connection and the required source is available. The customer experience is designed to minimise typing and guide the user through each capture step.
Completion time can vary when document capture is required, image quality is poor, an external data source is slow or unavailable, or the result needs manual review. WhoYou works with each client to select the checks and exception process that provide the right balance between speed, fraud protection and compliance.
Yes. Organisations do not have to apply the same level of verification to every customer or interaction. WhoYou services can be introduced at different points in a journey, allowing a business to begin with lighter identity or data checks and trigger biometric, document or additional risk checks when the customer's activity or risk profile justifies them.
The organisation defines when each check should occur and how different results should be handled. This can reduce unnecessary friction and verification cost while preserving stronger controls for higher-risk customers, transactions and account events.
Yes. WhoYou can be used wherever a business needs confidence that the person requesting an action is the genuine customer. A secure verification request can be triggered during password or account recovery, contact-detail changes, bank-detail updates, insurance claims, withdrawals, payouts, high-value transactions or other sensitive events.
The journey can use a fresh biometric and liveness check and compare it with a trusted source or a previously verified enrolment. The business then applies its own rules to approve, decline or refer the request for review.
WhoYou One Time Verification, or OTV, is a secure identity-verification request created for a specific person and interaction. Unlike a traditional one-time password, which mainly proves access to a phone number or email address, OTV can ask the person to prove their identity using a face, fingerprint or identity document.
Each request has a unique link and reference or PIN for traceability. OTV can be used for remote onboarding, customer authentication, claims, payouts, account changes, supplier or employee verification and other situations where a business needs reliable evidence of who completed the process. The reference identifies the verification request; it is not, by itself, proof of identity.
Yes. Where the client is authorised to perform the check and the service is available, WhoYou can validate a South African ID number against Department of Home Affairs sources.
The information returned depends on the selected service, the client's permissions and source availability. It may include the person's names, surname, date of birth, gender, life status, marital status, ID issue information, smart ID status, ID sequence information, blocked-ID indicators and the availability of a Home Affairs biometric or photograph. A response also identifies the source used and the outcome of the check, helping the client understand what was verified rather than receiving only a pass or fail result.
WhoYou can route the verification through an approved alternative path, depending on the client's configuration. This may include using an acceptable previously verified record, consulting an alternative authorised source, asking the customer to capture an identity document, or sending the result to an exception process for review.
For example, if a Home Affairs photograph is unavailable or DHA cannot be reached, the customer may be asked to capture a smart ID card, green barcoded ID book or passport. The document information and photograph can then be extracted and compared with the customer's live selfie. The result should clearly show which source and method were used so the client does not mistake a fallback check for a live DHA verification.
WhoYou can use securely held, previously verified identity data where this is lawful, appropriate and permitted by the client's rules. An acceptable cached record can improve availability, reduce repeat capture and avoid an unnecessary live source call. The verification result identifies whether information came from DHA directly, a WhoYou repository, another approved source or the customer's document.
A live DHA lookup can be required when no acceptable cached record exists, the record is older than the agreed freshness threshold, the use case requires current source data, or the client's policy specifically requires a live check. Cache age, freshness rules, fallback behaviour and billing treatment should be agreed for each implementation.
The customer securely captures a live facial image or fingerprint using a supported device. WhoYou first assesses the capture quality and, for facial verification, performs liveness and anti-spoofing checks. The biometric is then converted into a secure mathematical representation and compared with an approved reference.
Depending on the journey, the reference may be a photograph or fingerprint obtained from an authorised Home Affairs source, a photograph extracted from a verified identity document, or a biometric that the customer previously enrolled and successfully verified. WhoYou returns the match outcome and relevant score or status so that the client can apply its own acceptance, rejection or review rules.
Yes. WhoYou's facial verification includes liveness and anti-spoofing controls designed to distinguish a real person from presentation and injection attacks involving photographs, videos, masks or manipulated digital content.
The biometric stack uses layered controls that include checks during capture, passive liveness analysis, injection-attack protection and dedicated deepfake detection. The purpose is to assess both whether the face matches the trusted reference and whether a genuine person is participating in the verification at that moment. No biometric control should be treated as infallible, so clients can combine these results with document, device, data and business-risk signals where appropriate.
An older Home Affairs photograph can make a genuine customer's appearance more difficult to match. WhoYou uses biometric scores and configured thresholds to distinguish clear matches from results that require another step. An inconclusive result does not have to mean an automatic rejection: the journey can request a better capture, use document capture, consult another trusted source or refer the case for review.
Once a customer has successfully matched a new selfie against a trusted source, that verified image can be enrolled as a more recent reference for future authentication, subject to the client's configuration and lawful processing requirements. This can improve future customer experience while preserving the original verification trail.
Yes. WhoYou supports verification journeys for South African smart ID cards, green barcoded ID books and passports. Depending on the document, WhoYou can capture the document, extract information using barcode, machine-readable-zone or optical-character-recognition technology, extract the document photograph and compare it with a live selfie.
The checks available differ by document type and country. Document capture is therefore one part of a layered process: the result should show what data was extracted, what source was used, whether the face comparison succeeded and whether any element needs review.
When an authoritative government lookup is not available, WhoYou can use a document-led verification journey. The customer captures their passport or supported identity document and completes a live selfie. WhoYou can extract identity information from the document's machine-readable zone or visible fields, assess the document and compare its photograph with the live person.
WhoYou supports document types across more than 130 countries. In South Africa, additional checks may also be available for certain immigration permits, refugee identities or related records. The precise level of validation depends on the issuing country, document type and data sources available, and the result should distinguish document-based verification from a direct government-source match.
WhoYou can be integrated through APIs, secure hosted verification links, portal-based workflows and configured result notifications. A client can embed verification into a website or application, trigger it from a CRM, policy or case-management system, or allow an authorised employee to create and send a request manually.
The implementation can be designed around the client's existing customer journey rather than requiring it to replace its core systems. WhoYou works with the client to define the checks, request and result fields, references, exception paths, security controls and audit evidence required for the use case.
Yes. WhoYou provides APIs for identity, biometric, compliance and data services, together with technical documentation to support implementation. The APIs allow a client to initiate checks, pass client and transaction references, retrieve or receive results and connect those results to its own decision and case-management processes.
Access to specific endpoints and data sources depends on the WhoYou products contracted, the client's authorisation and any onboarding requirements imposed by the underlying source. WhoYou's technical team can provide the relevant credentials, test environment, specifications and implementation support.
Yes. Authorised users can use the WhoYou customer portal to create and share verification requests, view customers, manage incomplete or exception cases and generate or download verification reports. This enables a business to begin verifying customers without first building a full API integration.
The portal is particularly useful for proof-of-concept projects, lower-volume processes, call centres and operational teams that need to send an individual verification request. Clients can later integrate through APIs when they want greater automation or a fully embedded customer journey.
Verification links can be sent directly by SMS or copied into an approved communication channel such as email or WhatsApp. They can also be presented as a QR code or launched directly in the user's browser. The delivery method should form part of the client's agreed workflow and customer communications.
The documented default expiry for an OTV request is 24 hours. An expired link or PIN cannot be used to retrieve or complete a new verification result. Where a different validity period is required, the available configuration should be confirmed during implementation. Shorter validity periods can reduce security exposure, while longer periods may be more practical for some customer journeys.
Yes. In an integrated implementation, WhoYou can return verification outcomes to the client's systems using the agreed API or result-notification workflow. Clients can also use a unique WhoYou PIN, client reference or transaction reference to associate the result with the correct customer or case and, where enabled, retrieve it later.
The integration should define how results are authenticated, what information is returned, how retries or duplicate notifications are handled and how long records remain retrievable. Clients that do not integrate can search for and export verification reports through the portal.
WhoYou provides a verification record showing what was requested, when the verification took place, which method and source were used, and the resulting status. Depending on the journey, the report may include the unique PIN or reference, timestamps, identity details, captured and reference image information, biometric or liveness outcomes, match scores, document-extraction results, source indicators and exception reasons.
Biometric-only and biometric-with-document-capture reports are available for the relevant journeys. Authorised users can search and export reports through the portal, and integrated clients can store the required result data in their own systems. The exact evidence retained and displayed is governed by the selected service, access permissions, retention rules and privacy requirements.
Yes. Verification results can be linked to and stored in a client's CRM, policy administration, claims, onboarding or case-management platform through an integration. A client reference can be included so that the WhoYou result is attached to the correct customer and transaction.
Clients should store only the information required for their lawful purpose and apply suitable access, encryption, retention and deletion controls. In many cases, storing the outcome, source, timestamp and WhoYou reference is preferable to copying all underlying identity or biometric evidence into multiple systems. The final data design should reflect the organisation's legal, audit and operational requirements.
Yes. WhoYou Verify can screen a new customer's selfie against the organisation's own Person of Interest list and, where contracted and lawfully enabled, WhoYou's broader Face of Interest repository. Potential matches can be surfaced before the verification completes so that the client can apply its chosen review, escalation or blocking rules.
WhoYou can also support controls for identifying repeated or unusual verification activity using the references and risk signals available in the configured solution. The precise repeat-attempt, velocity, device and cross-journey signals available should be confirmed for the client's implementation. A potential match or unusual pattern is a risk indicator and should be handled according to an approved investigation process rather than treated as proof of fraud on its own.
WhoYou applies security controls throughout capture, transmission, processing and storage. These include encrypted communications, encryption at rest, authenticated APIs, role-based and least-privilege access, multi-factor authentication, isolated processing environments, continuous monitoring and detailed audit logs. Biometric inputs are transformed into secure templates for matching, and sensitive data is not stored on the customer's device.
Client access is restricted to authorised users, services and agreed purposes. Environments, permissions and records are segregated to prevent unauthorised cross-client access. Where a contracted shared-intelligence feature such as Face of Interest screening is used, the governance, lawful basis and information returned must be defined separately; it does not give one client general access to another client's customer records.
WhoYou is designed to support POPIA-aligned identity verification through secure capture, access controls, encryption, audit trails, configurable customer notices and controlled retention. The verification journey can present the purpose of the check and obtain or record the appropriate customer acknowledgement or consent where consent is the applicable lawful basis.
Biometric information is special personal information under POPIA and requires particular care. Using WhoYou does not, on its own, make a client's entire process compliant. The client remains responsible for defining the lawful purpose and basis, giving an appropriate privacy notice, minimising the information collected, responding to data-subject rights and setting defensible retention rules. WhoYou and the client should also define their respective responsibilities in the applicable contracts and data-processing terms.
WhoYou pricing is tailored to the services selected, expected transaction volumes, data sources used, integration and support requirements. A verification journey may contain several separate components, for example an identity-data check, live DHA lookup, document check, biometric match, liveness check or fraud screening, and the commercial schedule should state how each is charged.
Creating or sending a verification request does not necessarily mean that every possible check has been performed. WhoYou provides usage and transaction reporting so clients can reconcile charges, and the exact billable event for every service is defined in the client's proposal or agreement.
WhoYou's web-based verification works on supported smartphones, tablets and computers with a suitable camera, a current browser, JavaScript enabled and a stable internet connection. Customers should use the device's normal browser where possible, because some in-app browsers restrict camera access. The latest supported-device and browser matrix should be checked for exact requirements.
If capture fails, the customer should confirm that camera permission has been granted, reopen the link in the device's default browser, use a stable internet connection and close other apps using the camera, clean the camera lens and move to even front-facing light, remove hats, sunglasses or anything obscuring the face, place the entire document in frame on a plain surface and avoid glare, and check that the verification link has not expired.
If the issue continues, the customer can retry on another supported device or contact the organisation that requested the verification or WhoYou support, quoting the verification reference without sending sensitive identity information over an unsecured channel.