Lighter Know Your Customer (KYC) checks aren’t always an option, especially if you’re working in a high-risk sector where stricter due diligence is mandatory. So, the all-time dilemma around KYC conversions remains the same throughout the years, even though technology has proven to be a huge help in identity verification in terms of user experience.
No more manual tapping or manually selecting your document’s issuing country; no more pop-ups with different verification windows and redirects, etc. However, the issue is that with AI and ID verification bypass attempts, for example, using deepfakes, are also getting harder to spot. So the friction, in some cases, remains vital to actually identify fraudulent patterns and remain KYC-compliant.
In brief:
- Compared to KYB, where the process requires multiple steps to collect corporate entity documents, individual client KYC is generally simpler.
- Overcomplicating standard ID verification flows by adding unnecessary steps that directly impact the user experience can increase abandonment rates.
- Minimal steps in KYC aren’t always the right approach, as fraud remains a real threat that online platforms need to manage adequately.
I explain the key areas that make or break your KYC workflow, highlight the importance of fraud prevention and dig into iDenfy’s recent in-house research on identity threat and how to manage fraud prevention vs. unnecessary friction in different industries. Keep reading to find interesting statistics and the full report below.
What is an Identity Threat?
An identity threat is an action/behavior or a certain activity that puts the user’s identity at risk during the KYC verification process. It is often linked to fraudulent bypassing attempts, such as using multi-accounting and duplicate details during the initial account opening stage that requires KYC. Other threat examples include ID document manipulation or the use of synthetic or stolen identities.
Not every KYC error or failed ID verification should be automatically determined as a threat or a type of fraud. Often, the friction and the lost user can also be a result of their own actions. This includes taking a photo of their ID document in poor lightinhg, entering personal information with typos, uploading an expired utility bill during the address verification, and so on.

For this reason, creating different KYC workflows and triggering reverification only when necessary and based on the correct risk signals is vital. Some vendors also have manual reviewers who double-check the software and its results in real-time. For example, if the user accidentally left a typo but the KYC details are genuine, and the system still rejected their verification, the human analyst can change the final decision and approve them. This saves time due to not having to resubmit or re-enter any data from the end-user’s perspective.
How Does a Standard Identity Verification Process Work?
The typical identity verification flow consists of a government-issued ID check and biometric verification (both active and passive liveness detection are commonly used). The third popular method is database verification, where certain details, like the user’s Social Security number (SSN), are cross-matched in the background to check if they match. In certain cases, such as in crypto, proof of address is required to approve and verify a new wallet.
Ultimately, identity verification checks if the person is legitimate before higher-risk situations, such as gaining access to a monetized service, such as opening a bank account on a fintech app. This is the most widely known use case, but there are other instances where KYC is used. For example, a standard government-issued ID check is used to extract the date of birth from the ID document and check a user’s age as part of the age verification process on an age-restricted app or e-commerce marketplace that, for example, sells alcohol.
Related: 3 Steps to KYC [Compliance Guide]
Why Does Fraud Prevention vs. Friction Matter in Identity Verification?
Effective fraud prevention is directly linked to your revenue. You want customers who are protected and feel safe when using your services. If there’s a breach or a non-compliance fine that brings bad PR, you can lose customers who tend to switch providers or constantly look for better options and don’t mind going to a competitor. The same principle applies to the KYC process.
A properly balanced KYC flow should:
- Identify fraudulent users and flag risk patterns without blocking legitimate users
- Fully automate identity verification for low-risk users, improving overall conversion
- Guide the user through the entire KYC flow (for example, explaining why the information is needed or how to position the ID into the frame)
If the initial identity verification step before the account creation on your platform is complex, the user might drop off and go to another service provider. So, the balance is super important, as it helps retain customers and ensure a high quality of your services from the very first interaction, while keeping the identity verification process top-notch in terms of both security and U/X.
UX Issues Impacting the KYC Abandonment Rate
A poor mobile experience if you’re an app service provider will kill KYC conversions, especially in cases when the user’s typical persona is skilled in this field. For example, if the user is trying to access their ordered eSIM service and they’re in a hurry while traveling, the ID verification prior to them accessing the eSIM needs to be quick.
This sort of user is often tech-savvy and has already completed a KYC check on another app/service. If something goes wrong, most likely, they’ll spam the Support team, or worse, switch to another provider, demanding a refund from you. Issues like chargebacks also arise in cases like this. However, it depends on the concrete industry and use case.
Standard user experience-related issues that result in a higher KYC abandonment rate include:
Too Many Fields at the Very First Interaction
If the user is asked to enter their personal information again, even though they have just previously added their full name and linked their KYC details in another step, they will be put off. A good experience is when there’s minimal manual input.
It also reduces the chances of leaving typos in the user’s name, as in cases like this, the system then flags it as a mismatch. Other similar examples, like long forms or asking for details that OCR extracts (address information sometimes as well, depending on the KYC document and jurisdiction), are unacceptable in today’s KYC standards.
Poor Selfie Capture Guidance
No tips on how to position the face, not auto capture of the user’s face, requiring extra tapping on the screen, or vague instructions that confuse the user even more also affect conversions.
You should always test the potential KYC software not only during the demo call but also using the sandbox environment to see how it responds in more “niche” cases, like using bad lighting on purpose and seeing if real-time instructions to move are provided to the user as a way to convert them and help them complete their ID verification.
Related: 10 Tips for Successful Identity Verification
No Clear Explanation Why KYC is Conducted
The first and most important step is to give the user all the trust signals, showing a clear purpose and explaining why you need their personal details in the first place. In certain industries that are more anonymous by nature, such as gambling or crypto, users hesitate to upload their ID document.
To soften the edges and make them feel more “at home” during KYC verification, you should explain the basics. For example, that you don’t store certain details, how long the IDV session will take with estimates and all steps make the U/X more pleasant. Elements like a progress bar help.
Redirects and Device Switching
Constant redirects, new windows, different branding and desktop-first KYC flows that force users to switch devices can be a hassle for some users. Your job is to ensure that even if the user is asked to scan the QR code and then take a photo on their phone, the process is smooth and guided.
Unsupported devices or issues like slow loading between steps can result in an abandoned KYC session. You don’t want genuine users to start over and over again if the fault is on your system’s side.
Fraud vs. Friction Ratio in Different Industries
To see how the balance changes by sector, our team analyzed anonymized KYC verification data processed by iDenfy’s identity verification software, specifically using 20 different industries and their flagged verification sessions from May to August 2026.
To identify where the “fraud” and where the “friction” happened, there are two categories in the research:
- Possibly intentional fraud and linked signals, such as duplicate faces, reused ID documents, underage users and other AML-related red flags.
- Data mismatches and signals linked to friction and a disturbed user experience, but not fraud.
Mismatches include cases when the user was flagged by the KYC system, but their intentions were not fraudulent. For example, simple typos, missing middle names, outdated KYC details, or formatting differences rather than intentional fraud.
| Industry | Fraud share of flags | Mismatch share of flags | Most common flag |
|---|---|---|---|
| Crypto | 69.3% | 30.7% | Duplicate face checks (55.4%) |
| iGaming | 38.9% | 61.1% | Duplicate face checks (48.5%) |
| Fintech | 50.0% | 50.0% | Duplicate face checks (45.7%) |
| E-commerce | 13.3% | 86.7% | Name mismatch (52.4%) |
The research results show that identity threat models vary by industry
Key highlights from iDenfy’s Identity Threat report:
- iGaming generated the highest number of flagged KYC sessions among all industries in the report, reaching more than 40,800.
- Fintech shows the most balanced profile in terms of fraud vs. friction numbers, with 49.98% of flags linked to potential fraud and 50.02% to data mismatches.
- In crypto, 69% of flagged sessions were linked to intentional fraud attempts.
- In iGaming, 49% of flagged KYC sessions indicated repeated use of the same identity across accounts.
- In e-commerce, most 87% of flagged KYC sessions come from data mismatches, which is the opposite of crypto.
So, there’s no magic trick here. You need to automate repetitive tasks and keep users informed throughout the whole identity verification process to reduce unwanted friction. iDenfy’s data shows that users tend to benefit from doc-based checks + selfie biometrics with active liveness and passive liveness checks.
You should collect information only if it’s needed and trigger different IDV flows. This helps keep the process fast and simple, while still complying with the needed KYC obligations and common fraudulent bypass attempts.
For more details, get a demo and download the full report for free.