Frequently Asked Questions

Common questions about WhoYou verification, KYC, biometrics, integration, privacy and pricing.

About KYC and WhoYou

1. What is KYC, and why does it matter to regulated businesses in South Africa?

Know Your Customer (KYC) is the process a business uses to establish and verify who its customers are and assess the risks associated with doing business with them. For accountable institutions in South Africa, KYC forms part of broader customer due diligence obligations under the Financial Intelligence Centre Act (FICA).

Effective KYC helps businesses prevent identity fraud, money laundering and other financial crime while creating reliable customer records and an auditable compliance process. It should be proportionate to the risk involved: lower-risk interactions may require fewer checks, while higher-risk customers or transactions may require stronger verification and additional due diligence.

2. What is the difference between KYC, FICA, AML and identity verification?

These terms are related, but they are not interchangeable. KYC is the process of identifying a customer, verifying their identity and understanding the risk they may present. FICA is the South African law that places customer due diligence, record-keeping, reporting and other obligations on accountable institutions. AML, or anti-money laundering, is the broader framework of controls used to prevent, detect and report money laundering and related financial crime. Identity verification is one component of KYC. It confirms that the identity information supplied is valid and, where biometrics are used, that the person presenting it is the genuine identity holder.

WhoYou provides identity, biometric, data and compliance services that organisations can use as building blocks within their wider KYC and AML programmes.

3. What does WhoYou do beyond a basic ID number check?

WhoYou provides digital identity infrastructure across the customer lifecycle. Depending on the solution selected, businesses can validate identity information against trusted sources, verify faces or fingerprints, perform liveness and anti-spoofing checks, capture and assess identity documents, screen against risk data, manage exceptions and retain an audit trail of the verification.

WhoYou also provides access to government, bureau and third-party data services through a unified platform. This enables businesses to support onboarding, ongoing authentication, fraud prevention, compliance checks, customer-data enrichment and other identity-sensitive processes without integrating separately with every underlying source.

4. Which industries and business use cases does WhoYou support?

WhoYou supports regulated and identity-sensitive organisations across sectors including banking, fintech, insurance, iGaming, telecommunications, retail, healthcare, government, automotive, education, travel, logistics and security services.

Common use cases include digital customer onboarding, KYC and FICA checks, biometric authentication, policyholder or claimant verification, secure payouts, account recovery, bank-detail changes, SIM or account activation, fraud screening, customer-data enrichment and ongoing identity management. The verification journey can be tailored to the risks, systems and customer experience requirements of each organisation.

5. Can WhoYou support both customer onboarding and ongoing identity authentication?

Yes. WhoYou can verify a person during onboarding and authenticate them again when a later interaction carries additional risk. For example, a business may request biometric authentication when a customer resets a password, changes contact or bank details, submits a claim, requests a payout or performs another sensitive action.

This approach helps organisations move beyond once-off KYC. A previously verified identity can become the trusted foundation for future authentication, subject to the organisation's risk rules, consent requirements and configured verification process.

How verification works

6. How does WhoYou's digital identity verification process work?

The exact journey depends on the customer's country, the information available and the checks selected by the organisation. A typical process: the customer opens a secure verification link or begins the process inside the organisation's digital journey, the purpose of the verification and privacy or consent information are presented, the customer supplies an ID number or passport information and may capture a selfie, fingerprint or identity document, WhoYou performs the configured checks (data-source validation, document extraction, biometric matching, liveness detection, fraud screening), and a result and supporting evidence are returned to the organisation through the portal, an API or an integrated workflow.

If a preferred source or biometric is unavailable, the journey can follow an approved alternative path, such as document capture or exception review.

7. How quickly can customers complete an identity verification?

Simple biometric or data-verification journeys can often be completed in seconds, provided the customer has a supported device, a stable connection and the required source is available. The customer experience is designed to minimise typing and guide the user through each capture step.

Completion time can vary when document capture is required, image quality is poor, an external data source is slow or unavailable, or the result needs manual review. WhoYou works with each client to select the checks and exception process that provide the right balance between speed, fraud protection and compliance.

8. Can we use staged or risk-based KYC and trigger stronger verification only when required?

Yes. Organisations do not have to apply the same level of verification to every customer or interaction. WhoYou services can be introduced at different points in a journey, allowing a business to begin with lighter identity or data checks and trigger biometric, document or additional risk checks when the customer's activity or risk profile justifies them.

The organisation defines when each check should occur and how different results should be handled. This can reduce unnecessary friction and verification cost while preserving stronger controls for higher-risk customers, transactions and account events.

9. Can WhoYou authenticate customers during password resets, bank-detail changes, claims, payouts and other high-risk interactions?

Yes. WhoYou can be used wherever a business needs confidence that the person requesting an action is the genuine customer. A secure verification request can be triggered during password or account recovery, contact-detail changes, bank-detail updates, insurance claims, withdrawals, payouts, high-value transactions or other sensitive events.

The journey can use a fresh biometric and liveness check and compare it with a trusted source or a previously verified enrolment. The business then applies its own rules to approve, decline or refer the request for review.

10. What is WhoYou One Time Verification (OTV), and when should it be used?

WhoYou One Time Verification, or OTV, is a secure identity-verification request created for a specific person and interaction. Unlike a traditional one-time password, which mainly proves access to a phone number or email address, OTV can ask the person to prove their identity using a face, fingerprint or identity document.

Each request has a unique link and reference or PIN for traceability. OTV can be used for remote onboarding, customer authentication, claims, payouts, account changes, supplier or employee verification and other situations where a business needs reliable evidence of who completed the process. The reference identifies the verification request; it is not, by itself, proof of identity.

Biometrics, Home Affairs, documents and passports

11. Can WhoYou verify a South African ID number against Department of Home Affairs data, and what information is returned?

Yes. Where the client is authorised to perform the check and the service is available, WhoYou can validate a South African ID number against Department of Home Affairs sources.

The information returned depends on the selected service, the client's permissions and source availability. It may include the person's names, surname, date of birth, gender, life status, marital status, ID issue information, smart ID status, ID sequence information, blocked-ID indicators and the availability of a Home Affairs biometric or photograph. A response also identifies the source used and the outcome of the check, helping the client understand what was verified rather than receiving only a pass or fail result.

12. What happens when Home Affairs or another verification data source is unavailable?

WhoYou can route the verification through an approved alternative path, depending on the client's configuration. This may include using an acceptable previously verified record, consulting an alternative authorised source, asking the customer to capture an identity document, or sending the result to an exception process for review.

For example, if a Home Affairs photograph is unavailable or DHA cannot be reached, the customer may be asked to capture a smart ID card, green barcoded ID book or passport. The document information and photograph can then be extracted and compared with the customer's live selfie. The result should clearly show which source and method were used so the client does not mistake a fallback check for a live DHA verification.

13. Does WhoYou use non real-time identity data, and when is a live DHA lookup performed?

WhoYou can use securely held, previously verified identity data where this is lawful, appropriate and permitted by the client's rules. An acceptable cached record can improve availability, reduce repeat capture and avoid an unnecessary live source call. The verification result identifies whether information came from DHA directly, a WhoYou repository, another approved source or the customer's document.

A live DHA lookup can be required when no acceptable cached record exists, the record is older than the agreed freshness threshold, the use case requires current source data, or the client's policy specifically requires a live check. Cache age, freshness rules, fallback behaviour and billing treatment should be agreed for each implementation.

14. How does WhoYou's biometric identity verification work, and what is the customer's selfie or fingerprint compared against?

The customer securely captures a live facial image or fingerprint using a supported device. WhoYou first assesses the capture quality and, for facial verification, performs liveness and anti-spoofing checks. The biometric is then converted into a secure mathematical representation and compared with an approved reference.

Depending on the journey, the reference may be a photograph or fingerprint obtained from an authorised Home Affairs source, a photograph extracted from a verified identity document, or a biometric that the customer previously enrolled and successfully verified. WhoYou returns the match outcome and relevant score or status so that the client can apply its own acceptance, rejection or review rules.

15. Does WhoYou use liveness detection, anti-spoofing and deepfake protection?

Yes. WhoYou's facial verification includes liveness and anti-spoofing controls designed to distinguish a real person from presentation and injection attacks involving photographs, videos, masks or manipulated digital content.

The biometric stack uses layered controls that include checks during capture, passive liveness analysis, injection-attack protection and dedicated deepfake detection. The purpose is to assess both whether the face matches the trusted reference and whether a genuine person is participating in the verification at that moment. No biometric control should be treated as infallible, so clients can combine these results with document, device, data and business-risk signals where appropriate.

16. What happens when a Home Affairs photo is old or a biometric match is inconclusive?

An older Home Affairs photograph can make a genuine customer's appearance more difficult to match. WhoYou uses biometric scores and configured thresholds to distinguish clear matches from results that require another step. An inconclusive result does not have to mean an automatic rejection: the journey can request a better capture, use document capture, consult another trusted source or refer the case for review.

Once a customer has successfully matched a new selfie against a trusted source, that verified image can be enrolled as a more recent reference for future authentication, subject to the client's configuration and lawful processing requirements. This can improve future customer experience while preserving the original verification trail.

17. Can WhoYou verify smart ID cards, green ID books and passports?

Yes. WhoYou supports verification journeys for South African smart ID cards, green barcoded ID books and passports. Depending on the document, WhoYou can capture the document, extract information using barcode, machine-readable-zone or optical-character-recognition technology, extract the document photograph and compare it with a live selfie.

The checks available differ by document type and country. Document capture is therefore one part of a layered process: the result should show what data was extracted, what source was used, whether the face comparison succeeded and whether any element needs review.

18. How does WhoYou verify foreign nationals or passports when no government API is available?

When an authoritative government lookup is not available, WhoYou can use a document-led verification journey. The customer captures their passport or supported identity document and completes a live selfie. WhoYou can extract identity information from the document's machine-readable zone or visible fields, assess the document and compare its photograph with the live person.

WhoYou supports document types across more than 130 countries. In South Africa, additional checks may also be available for certain immigration permits, refugee identities or related records. The precise level of validation depends on the issuing country, document type and data sources available, and the result should distinguish document-based verification from a direct government-source match.

Integration and verification workflows

19. How does WhoYou integrate with our existing systems and customer journeys?

WhoYou can be integrated through APIs, secure hosted verification links, portal-based workflows and configured result notifications. A client can embed verification into a website or application, trigger it from a CRM, policy or case-management system, or allow an authorised employee to create and send a request manually.

The implementation can be designed around the client's existing customer journey rather than requiring it to replace its core systems. WhoYou works with the client to define the checks, request and result fields, references, exception paths, security controls and audit evidence required for the use case.

20. Does WhoYou provide an identity verification API and developer documentation?

Yes. WhoYou provides APIs for identity, biometric, compliance and data services, together with technical documentation to support implementation. The APIs allow a client to initiate checks, pass client and transaction references, retrieve or receive results and connect those results to its own decision and case-management processes.

Access to specific endpoints and data sources depends on the WhoYou products contracted, the client's authorisation and any onboarding requirements imposed by the underlying source. WhoYou's technical team can provide the relevant credentials, test environment, specifications and implementation support.

21. Can we use WhoYou through a portal without completing a full API integration?

Yes. Authorised users can use the WhoYou customer portal to create and share verification requests, view customers, manage incomplete or exception cases and generate or download verification reports. This enables a business to begin verifying customers without first building a full API integration.

The portal is particularly useful for proof-of-concept projects, lower-volume processes, call centres and operational teams that need to send an individual verification request. Clients can later integrate through APIs when they want greater automation or a fully embedded customer journey.

22. Can verification links be delivered by SMS, WhatsApp or email, and how long do they remain valid?

Verification links can be sent directly by SMS or copied into an approved communication channel such as email or WhatsApp. They can also be presented as a QR code or launched directly in the user's browser. The delivery method should form part of the client's agreed workflow and customer communications.

The documented default expiry for an OTV request is 24 hours. An expired link or PIN cannot be used to retrieve or complete a new verification result. Where a different validity period is required, the available configuration should be confirmed during implementation. Shorter validity periods can reduce security exposure, while longer periods may be more practical for some customer journeys.

23. Can WhoYou return results through APIs or webhooks and retrieve them later using a reference or PIN?

Yes. In an integrated implementation, WhoYou can return verification outcomes to the client's systems using the agreed API or result-notification workflow. Clients can also use a unique WhoYou PIN, client reference or transaction reference to associate the result with the correct customer or case and, where enabled, retrieve it later.

The integration should define how results are authenticated, what information is returned, how retries or duplicate notifications are handled and how long records remain retrievable. Clients that do not integrate can search for and export verification reports through the portal.

Fraud, auditability, privacy and compliance

24. What evidence, verification report and audit trail does WhoYou provide after a verification?

WhoYou provides a verification record showing what was requested, when the verification took place, which method and source were used, and the resulting status. Depending on the journey, the report may include the unique PIN or reference, timestamps, identity details, captured and reference image information, biometric or liveness outcomes, match scores, document-extraction results, source indicators and exception reasons.

Biometric-only and biometric-with-document-capture reports are available for the relevant journeys. Authorised users can search and export reports through the portal, and integrated clients can store the required result data in their own systems. The exact evidence retained and displayed is governed by the selected service, access permissions, retention rules and privacy requirements.

25. Can verification records be stored in our CRM, policy administration or case-management system?

Yes. Verification results can be linked to and stored in a client's CRM, policy administration, claims, onboarding or case-management platform through an integration. A client reference can be included so that the WhoYou result is attached to the correct customer and transaction.

Clients should store only the information required for their lawful purpose and apply suitable access, encryption, retention and deletion controls. In many cases, storing the outcome, source, timestamp and WhoYou reference is preferable to copying all underlying identity or biometric evidence into multiple systems. The final data design should reflect the organisation's legal, audit and operational requirements.

26. Can WhoYou screen customers against known or flagged faces and identify suspicious repeat attempts?

Yes. WhoYou Verify can screen a new customer's selfie against the organisation's own Person of Interest list and, where contracted and lawfully enabled, WhoYou's broader Face of Interest repository. Potential matches can be surfaced before the verification completes so that the client can apply its chosen review, escalation or blocking rules.

WhoYou can also support controls for identifying repeated or unusual verification activity using the references and risk signals available in the configured solution. The precise repeat-attempt, velocity, device and cross-journey signals available should be confirmed for the client's implementation. A potential match or unusual pattern is a risk indicator and should be handled according to an approved investigation process rather than treated as proof of fraud on its own.

27. How does WhoYou protect personal and biometric data and keep each client's information separate?

WhoYou applies security controls throughout capture, transmission, processing and storage. These include encrypted communications, encryption at rest, authenticated APIs, role-based and least-privilege access, multi-factor authentication, isolated processing environments, continuous monitoring and detailed audit logs. Biometric inputs are transformed into secure templates for matching, and sensitive data is not stored on the customer's device.

Client access is restricted to authorised users, services and agreed purposes. Environments, permissions and records are segregated to prevent unauthorised cross-client access. Where a contracted shared-intelligence feature such as Face of Interest screening is used, the governance, lawful basis and information returned must be defined separately; it does not give one client general access to another client's customer records.

28. How does WhoYou support POPIA compliance, customer consent and lawful biometric-data processing?

WhoYou is designed to support POPIA-aligned identity verification through secure capture, access controls, encryption, audit trails, configurable customer notices and controlled retention. The verification journey can present the purpose of the check and obtain or record the appropriate customer acknowledgement or consent where consent is the applicable lawful basis.

Biometric information is special personal information under POPIA and requires particular care. Using WhoYou does not, on its own, make a client's entire process compliant. The client remains responsible for defining the lawful purpose and basis, giving an appropriate privacy notice, minimising the information collected, responding to data-subject rights and setting defensible retention rules. WhoYou and the client should also define their respective responsibilities in the applicable contracts and data-processing terms.

Pricing and billing

29. How is WhoYou priced, and when do failed attempts, abandoned journeys, cached checks or live DHA lookups become billable?

WhoYou pricing is tailored to the services selected, expected transaction volumes, data sources used, integration and support requirements. A verification journey may contain several separate components, for example an identity-data check, live DHA lookup, document check, biometric match, liveness check or fraud screening, and the commercial schedule should state how each is charged.

Creating or sending a verification request does not necessarily mean that every possible check has been performed. WhoYou provides usage and transaction reporting so clients can reconcile charges, and the exact billable event for every service is defined in the client's proposal or agreement.

Devices and troubleshooting

30. Which devices and browsers does WhoYou support, and what should a customer do when camera, selfie or document capture fails?

WhoYou's web-based verification works on supported smartphones, tablets and computers with a suitable camera, a current browser, JavaScript enabled and a stable internet connection. Customers should use the device's normal browser where possible, because some in-app browsers restrict camera access. The latest supported-device and browser matrix should be checked for exact requirements.

If capture fails, the customer should confirm that camera permission has been granted, reopen the link in the device's default browser, use a stable internet connection and close other apps using the camera, clean the camera lens and move to even front-facing light, remove hats, sunglasses or anything obscuring the face, place the entire document in frame on a plain surface and avoid glare, and check that the verification link has not expired.

If the issue continues, the customer can retry on another supported device or contact the organisation that requested the verification or WhoYou support, quoting the verification reference without sending sensitive identity information over an unsecured channel.

Still have a question?

Our team is happy to help with anything not covered here.

Contact us