All posts
4 min readOpenKYC Team

The True Cost of KYC: Why Identity Verification Is a $200B+ Problem

kyceconomics

Ask a fintech founder what KYC costs and they'll quote their vendor's per-check price. That number is the visible tip of something much larger: compliance headcount, abandoned signups, stored-PII liability, and an industry-wide habit of verifying the same person over and over. Add it all up and, by some estimates, the world spends over $200 billion a year on financial-crime compliance, with identity verification sitting at the center of the bill.

The compliance bill nobody itemizes

Direct verification fees are the easy part to count. A document-plus-biometrics check costs a platform somewhere between one and several dollars per attempt, more for enhanced due diligence. But the per-check fee is dwarfed by everything around it.

Industry estimates put financial-crime compliance spend for banks and fintechs in the hundreds of billions globally each year, and surveys of large institutions regularly find individual banks spending tens or even hundreds of millions annually on KYC operations alone. Most of that is not software. It's people. Analysts reviewing flagged documents, remediation teams refreshing stale customer files, compliance officers reconciling vendor outputs with regulatory expectations. Periodic re-verification of existing customers, often overlooked in cost models, can consume as much budget as onboarding new ones.

For a regulated business, this is not discretionary spend. It scales with customer count, and it never stops.

The waste of verifying the same person twice

Here is the part that should bother economists: the overwhelming majority of KYC checks verify people who have already been verified, often many times, often recently, often to an identical standard.

Every new account at every regulated platform triggers a fresh check, because each business is legally on the hook for its own due diligence and has no portable way to rely on anyone else's work. The same passport gets photographed, uploaded, OCR'd, and screened at the bank, the broker, the exchange, the lending app, and the neobank. Five businesses pay five times to learn one fact.

This is pure deadweight loss. No fraud is prevented by the fourth check that the first three missed; no regulator is better informed. The duplication exists because the result of a check has never been portable, a problem that reusable KYC was designed specifically to eliminate.

Abandonment: the cost that never shows up in the budget

The most expensive part of KYC may be the customers you never get. Onboarding flows that demand document uploads and selfie checks lose a meaningful share of applicants before completion. Industry studies have repeatedly found that a substantial fraction of users abandon financial onboarding when verification gets slow or fiddly, and that abandonment climbs sharply with every extra minute and every failed capture attempt.

Think about what that means in unit economics. You paid to acquire the user. They wanted your product. Then a glare on a passport photo, a webcam permission prompt, or a "we'll review your documents within 48 hours" email ended the relationship. The verification fee for that user was wasted, the acquisition cost was wasted, and the lifetime value went to a competitor with a smoother flow.

KYC friction is a conversion problem wearing a compliance badge, and finance teams rarely attribute the lost revenue back to it.

Stored PII is a liability, not an asset

Every completed check leaves a residue: passport scans, selfies, proof-of-address documents, dates of birth. Multiply by every customer and every platform, and the industry has built thousands of identity honeypots, each one a breach waiting to be expensive.

The costs when it goes wrong are well documented in kind if not in precise number: regulatory fines under GDPR and its cousins, breach-notification and credit-monitoring expenses, litigation, and the slow-burn brand damage of telling customers their identity documents are on a leak forum. Identity data is among the most damaging categories to lose, because unlike a password, a passport can't be rotated.

The uncomfortable conclusion: most platforms store this data not because they want it, but because the verification model forces them to collect it. A model where businesses verify a credential without warehousing the underlying documents removes the honeypot instead of guarding it.

Small platforms pay the steepest price

KYC costs are regressive. A large bank amortizes its compliance machine across millions of customers; a seed-stage fintech pays startup-tier vendor pricing, can't negotiate volume discounts, and burns founder time on compliance instead of product. The per-customer cost of doing KYC properly is, by most accounts, several times higher for small platforms than for incumbents.

This asymmetry quietly shapes the market. It raises the barrier to launching anything regulated, pushes startups toward banking-as-a-service intermediaries who take their own cut, and entrenches whoever already has the compliance infrastructure. Cheaper, portable verification isn't just an efficiency gain. It's a competitive equalizer.

What the bill is really paying for

Step back and the picture is stark: hundreds of billions in annual spend, much of it duplicated effort, financing a system that still leaks customers at onboarding and accumulates breach liability as a by-product. The spend isn't buying proportionate security. It's buying repetition.

The fix is structural, not incremental. When a verification can be performed once by a certified issuer and reused across services as a user-held credential, the duplicated checks collapse into one, onboarding friction drops to a consent tap, and the PII honeypots stop growing. Adjacent infrastructure is heading the same way: open banking is already reshaping how identity data moves between institutions, normalizing the idea that customers, not silos, route their own data.

Where OpenKYC fits

OpenKYC is building a reusable KYC marketplace on open standards (W3C Verifiable Credentials, OpenID4VC): verify once, hold the credential in your own wallet, reuse it everywhere, and earn every time it's used. Join the waitlist at openkyc.org.

Verify once. Use everywhere. Earn every time.

OpenKYC is building the reusable KYC marketplace on open identity standards. Be first in line.

Join the waitlist